<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Worpress 2.7.1 wp-comments-post.php XSS exploit</title>
	<atom:link href="http://securitygyan.com/2009/05/03/worpress-271-wp-comments-postphp-xss-exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://securitygyan.com/2009/05/03/worpress-271-wp-comments-postphp-xss-exploit/</link>
	<description>World of information security</description>
	<lastBuildDate>Sun, 30 Jan 2011 09:36:30 -0800</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
	<item>
		<title>By: Dolly</title>
		<link>http://securitygyan.com/2009/05/03/worpress-271-wp-comments-postphp-xss-exploit/comment-page-1/#comment-804</link>
		<dc:creator>Dolly</dc:creator>
		<pubDate>Mon, 15 Feb 2010 00:08:11 +0000</pubDate>
		<guid isPermaLink="false">http://securitygyan.com/?p=56#comment-804</guid>
		<description>Interesting, did you plan to continue this article?
 &lt;a href=&quot;http://www.getwartool.com/&quot; rel=&quot;nofollow&quot;&gt;Dolly&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>Interesting, did you plan to continue this article?<br />
 <a href="http://www.getwartool.com/" rel="nofollow">Dolly</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tak</title>
		<link>http://securitygyan.com/2009/05/03/worpress-271-wp-comments-postphp-xss-exploit/comment-page-1/#comment-800</link>
		<dc:creator>Tak</dc:creator>
		<pubDate>Thu, 07 Jan 2010 17:29:39 +0000</pubDate>
		<guid isPermaLink="false">http://securitygyan.com/?p=56#comment-800</guid>
		<description>nice detection man..
i was also find some xss vul&#039;s.
okay keep it up</description>
		<content:encoded><![CDATA[<p>nice detection man..<br />
i was also find some xss vul&#8217;s.<br />
okay keep it up</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: LeraJenkins</title>
		<link>http://securitygyan.com/2009/05/03/worpress-271-wp-comments-postphp-xss-exploit/comment-page-1/#comment-37</link>
		<dc:creator>LeraJenkins</dc:creator>
		<pubDate>Tue, 23 Jun 2009 08:03:23 +0000</pubDate>
		<guid isPermaLink="false">http://securitygyan.com/?p=56#comment-37</guid>
		<description>Clever things, speaks)</description>
		<content:encoded><![CDATA[<p>Clever things, speaks)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vikrant</title>
		<link>http://securitygyan.com/2009/05/03/worpress-271-wp-comments-postphp-xss-exploit/comment-page-1/#comment-11</link>
		<dc:creator>Vikrant</dc:creator>
		<pubDate>Mon, 04 May 2009 16:57:21 +0000</pubDate>
		<guid isPermaLink="false">http://securitygyan.com/?p=56#comment-11</guid>
		<description>Hi,

Good finding.Keep the good work up.

Wish you all the best


Vikrant</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>Good finding.Keep the good work up.</p>
<p>Wish you all the best</p>
<p>Vikrant</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WordPress Codex</title>
		<link>http://securitygyan.com/2009/05/03/worpress-271-wp-comments-postphp-xss-exploit/comment-page-1/#comment-10</link>
		<dc:creator>WordPress Codex</dc:creator>
		<pubDate>Mon, 04 May 2009 15:33:50 +0000</pubDate>
		<guid isPermaLink="false">http://securitygyan.com/?p=56#comment-10</guid>
		<description>

Only users with the &lt;a href=&quot;http://codex.wordpress.org/Roles_and_Capabilities#unfiltered_html&quot; rel=&quot;nofollow&quot;&gt;unfiltered_html capability&lt;/a&gt; can post unfiltered HTML markup or even Javascript code in pages, posts, and comments.

By default &lt;a href=&quot;http://codex.wordpress.org/Roles_and_Capabilities#Capability_vs._Role_Table&quot; rel=&quot;nofollow&quot;&gt;only the users in the roles admin or editor have this capability&lt;/a&gt; therefore there is no security bug at all cause only admins or editors (which are the two most highest roles in wordpress -by default-) and this users need to have this capability otherwise this users will be very limited specially cause they are normally the blog owners or well take a huge role on the wordpress powered site.

Regards</description>
		<content:encoded><![CDATA[<p>Only users with the <a href="http://codex.wordpress.org/Roles_and_Capabilities#unfiltered_html" rel="nofollow">unfiltered_html capability</a> can post unfiltered HTML markup or even Javascript code in pages, posts, and comments.</p>
<p>By default <a href="http://codex.wordpress.org/Roles_and_Capabilities#Capability_vs._Role_Table" rel="nofollow">only the users in the roles admin or editor have this capability</a> therefore there is no security bug at all cause only admins or editors (which are the two most highest roles in wordpress -by default-) and this users need to have this capability otherwise this users will be very limited specially cause they are normally the blog owners or well take a huge role on the wordpress powered site.</p>
<p>Regards</p>
]]></content:encoded>
	</item>
</channel>
</rss>

